PROFIDA LLC-FZ
Privacy Policy
This Privacy Policy explains how PROFIDA LLC-FZ (“PROFIDA”, “we”, “us”, or “our”) collects, uses, discloses, stores, and protects personal data when you visit our websites, contact us, work with us, or interact with services and authorised integrations that we operate for our clients.
It is intended to provide clear information under applicable privacy and data-protection laws, including the European Union General Data Protection Regulation (“GDPR”) and the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, where those laws apply.
1. Company information and scope
PROFIDA LLC-FZ
The Meydan Hotel, 6th Floor
Dubai, United Arab Emirates
TRN: 104235859600001
Website: www.profida.dk
Email: emil@profida.dk
Telephone: +971 58 509 8068
This Policy applies to PROFIDA websites and subdomains, our business-development and client-service activities, and the advertising, creative, analytics, reporting, moderation, and automation services we provide.
2. Our role as controller and processor
PROFIDA as controller
PROFIDA determines why and how personal data is processed when we operate our website, manage enquiries, market our own services, administer client and supplier relationships, secure our systems, recruit personnel, and comply with legal obligations.
PROFIDA as processor
When a client authorises us to access its advertising, ecommerce, analytics, attribution, social media, CRM, content, or related systems, we generally process relevant personal data on that client’s documented instructions. The client remains the controller and its own privacy notice also applies. Our contract and, where applicable, data-processing agreement with the client govern that processing.
3. Personal data we collect
The categories of personal data we process depend on your relationship with PROFIDA and the services or integrations you use. They may include:
- Identity and contact data: name, username, work email, telephone number, mailing or business address, job title, company, and relevant social or business account identifiers.
- Business relationship data: enquiries, proposals, contracts, meeting notes, service communications, support requests, invoices, billing contact details, and records of your preferences.
- Website and device data: IP address, browser and device type, operating system, approximate location, referral source, URL and campaign parameters, page views, interactions, timestamps, cookie identifiers, local-storage or session identifiers, and security logs.
- Client service data: information within client-authorised advertising, ecommerce, analytics, attribution, CRM, content, project-management, and communication systems that is necessary to perform our services.
- Advertising and performance data: business, account, campaign, ad set, ad, creative, audience-configuration, conversion, spend, revenue, attribution, and performance information.
- Social and engagement data: Facebook Page or Instagram business account information, posts, comments, message or interaction content, and limited public or platform-provided account information when a client enables a relevant workflow.
- Derived data: analyses, segments, recommendations, forecasts, classifications, summaries, quality checks, and other outputs created from the data described above.
- Personnel and applicant data: information voluntarily provided by applicants, employees, or contractors where relevant to recruitment or workforce administration.
Please do not send us passwords, two-factor codes, access tokens, full payment-card details, government identifiers, special-category personal data, or other unnecessary sensitive information unless we have expressly requested it through an approved secure process.
4. How we obtain personal data
We may obtain personal data directly from you when you visit our website, submit a form, book a meeting, communicate with us, enter into a contract, or use a service. We may also receive data from the organisation you represent, our clients, authorised advertising and ecommerce platforms, analytics and attribution providers, CRM and scheduling tools, social media platforms, service providers, fraud-prevention or security providers, and publicly available business sources.
Where our client supplies or authorises access to end-user data, the client is responsible for ensuring that it has an appropriate legal basis and has provided any required notice.
5. Why we process personal data
We use personal data for the following purposes:
- to respond to enquiries, prepare proposals, enter into contracts, onboard clients, and administer our business relationships;
- to provide performance marketing, media buying, creative strategy, content, analytics, reporting, moderation, automation, and related services;
- to connect and maintain client-authorised platforms, retrieve or update permitted data, monitor performance, and troubleshoot integrations;
- to personalise and improve our website, communications, service delivery, and customer support;
- to measure campaign and website performance, attribute traffic, build permitted audiences, and conduct remarketing where allowed;
- to send operational messages and, where permitted, relevant business marketing communications;
- to protect accounts, systems, personnel, clients, and users; prevent misuse or fraud; and investigate incidents;
- to maintain business, accounting, tax, compliance, and dispute records; and
- to comply with law, regulatory requirements, court orders, and lawful authority requests.
6. Legal bases
Where the GDPR or a similar legal-basis framework applies, we rely on one or more of the following:
- Contract: processing needed to take requested steps before a contract or to perform a contract with you or the organisation you represent.
- Legitimate interests: operating and improving our business and services, communicating with business contacts, measuring performance, maintaining security, preventing misuse, and establishing or defending legal claims, provided those interests are not overridden by your rights.
- Consent: optional cookies, certain marketing communications, or other processing where consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
- Legal obligation: processing required for accounting, tax, regulatory, employment, legal-process, or other statutory duties.
7. Meta, Facebook, and Instagram Platform Data
When a client or authorised user connects a Meta account or asset, PROFIDA may access Platform Data only through the permissions and products approved for the relevant integration. Depending on the service, this may include:
- business, ad-account, Facebook Page, and Instagram business account identifiers and authorised connection details;
- campaign, ad set, ad, creative, audience-configuration, spend, delivery, conversion, and insight data;
- Page or Instagram content, comments, comment text, limited commenter identifiers, and public profile information supplied by Meta when a client enables moderation or comment-intelligence functions; and
- technical logs required to maintain, secure, and troubleshoot the connection.
We use Meta Platform Data to provide the client-requested advertising, creative, reporting, analytics, moderation, and automation services; secure and troubleshoot integrations; and comply with Meta’s platform terms and applicable law. We apply data minimisation and avoid collecting commenter identity where it is not needed.
We do not sell Meta Platform Data or use it for unrelated advertising. Access is restricted to authorised personnel and service providers with a need to know. If authorisation is revoked, the client relationship ends, or deletion is validly requested, we disconnect the integration and delete or de-identify data under our control unless retention is required by law, security, fraud-prevention, or legal-claims obligations.
Instructions for revoking access and requesting deletion are available on our Data Deletion page.
8. Automation and artificial intelligence
We use software automation and may use AI-assisted tools to analyse performance, classify or summarise information, draft recommendations or creative materials, identify issues, and support service delivery. These tools may process relevant client or Platform Data under access controls and contractual safeguards appropriate to the service.
Consequential client decisions are reviewed through human workflows. We do not use website or Platform Data to make solely automated decisions about individuals that produce legal or similarly significant effects unless we provide a specific notice and have an appropriate lawful basis.
9. Cookies, analytics, and tracking technologies
Our website and service providers use technologies needed to deliver pages, maintain security, balance traffic, remember preferences, play embedded media, measure visits, attribute traffic, and improve performance. These technologies may include cookies, local storage, session storage, pixels, tags, and similar identifiers.
The current website configuration may use Webflow services, Google Analytics, Optibase, embedded video providers, and advertising or remarketing technologies. This may include Meta Pixel or related Meta measurement tools where enabled. These providers may receive device, browser, IP, page, interaction, referral, and identifier data under their own notices and our applicable agreements.
Where law requires consent, non-essential analytics, advertising, and remarketing technologies are used only after valid consent. You can use available site controls and your browser settings to block or delete cookies and local data. Blocking some technologies may affect videos, preferences, analytics, or other site functions.
10. Email marketing and remarketing
If you ask to receive updates or otherwise lawfully opt in, we may send relevant business communications. Each marketing email will provide an unsubscribe method. You may also opt out by contacting us.
Where permitted, we may use website activity or contact information to measure advertising and create or match audiences on advertising platforms. We do so only with an appropriate legal basis and subject to applicable platform terms. Opting out of marketing does not prevent operational communications concerning an active enquiry, contract, or service.
11. Who we share data with
We disclose personal data only where necessary and proportionate. Recipients may include:
- the client for whom we provide services and its authorised personnel;
- website, hosting, cloud, database, security, and backup providers, including Webflow;
- advertising and social platforms, including Meta, where an authorised integration or campaign requires it;
- ecommerce, analytics, attribution, CRM, scheduling, email, collaboration, automation, AI, payment, and professional service providers;
- approved employees, contractors, affiliates, and advisers subject to confidentiality obligations;
- authorities, courts, regulators, or other parties where disclosure is required or permitted by law or needed to protect rights, safety, and security; and
- a prospective buyer, successor, or counterparty in connection with a merger, financing, reorganisation, asset sale, or similar transaction, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data. Processors are required to use personal data only for authorised purposes and to protect it appropriately.
12. International transfers
PROFIDA is established in the United Arab Emirates and works with clients and providers in multiple countries. Personal data may therefore be processed in the UAE, the European Economic Area, the United Kingdom, the United States, and other locations where our providers operate.
Where a restricted international transfer requires safeguards, we use an available lawful mechanism such as an adequacy decision, standard contractual clauses, contractual protections, or another legally recognised safeguard, together with supplementary measures where appropriate.
13. Retention
We retain personal data only for as long as necessary for the purposes described in this Policy. The period depends on the type of data, the client relationship, platform requirements, security needs, limitation periods, and accounting or other legal obligations.
- Website and enquiry data is retained while an enquiry or legitimate business relationship remains active and is then reviewed for deletion or de-identification.
- Operational client and Platform Data is retained for the service term and an appropriate offboarding period, then deleted or de-identified unless the client instructs otherwise or law requires retention.
- Security and technical logs are retained for a limited period appropriate to investigation, reliability, and fraud prevention.
- Contract, invoice, tax, employment, and dispute records may be retained for the applicable statutory or claims period.
Data in backups is isolated from normal use and removed through scheduled backup rotation. Where immediate deletion is not technically possible, the data is restricted from further use until removal.
14. Security
We use reasonable technical and organisational measures designed to protect personal data, including access controls, least-privilege permissions, authentication, encryption where supported, service-provider review, logging, staff confidentiality, and incident-response procedures. No system is completely secure, but we review our controls and adapt them to the nature and risk of the processing.
15. Your privacy rights
Depending on your location and the law that applies, you may have the right to:
- ask whether we process your personal data and receive access to it;
- correct incomplete or inaccurate personal data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive personal data you provided in a portable format where applicable;
- withdraw consent at any time; and
- complain to the competent data-protection authority in your country.
To exercise a right, email emil@profida.dk. We may request limited information to verify your identity and authority. We respond without undue delay and, where the GDPR applies, generally within one month. If PROFIDA processes the data only for a client, we may direct the request to that client or assist the client in responding.
16. Children
Our website and services are directed to businesses and are not intended for children. We do not knowingly collect personal data from children through this website. If you believe a child has provided personal data to us, contact us so we can investigate and delete it where appropriate.
17. Third-party websites and services
Our website and services may link to or embed third-party websites, applications, or content. Those third parties operate independently and their handling of personal data is governed by their own privacy notices. We encourage you to review those notices before using the relevant service.
18. Changes to this Policy
We may update this Policy when our services, integrations, or legal obligations change. We will post the revised version on this page and update the date above. If a change materially affects how we use personal data, we will provide additional notice where required.
19. Contact
Questions, concerns, and privacy requests may be sent to:
PROFIDA LLC-FZ
The Meydan Hotel, 6th Floor
Dubai, United Arab Emirates
Email: emil@profida.dk
Telephone: +971 58 509 8068
